Trump orders mapping of software, suppliers across defense chains

President Trump signed an executive order directing the Department of War to require defense contractors to map software, hardware and supplier tiers and report significant supply-chain risks.

President Trump signed an executive order directing the Department of War to require defense contractors to map software, hardware and supplier tiers across critical defense supply chains and to report significant risks uncovered during supplier vetting.

The order directs the Secretary of War to develop policies within 180 days that require mapping all tiers of suppliers supporting national security acquisitions. Implementing regulations must follow within 90 days after those policies are issued. The guidance calls for an “indentured Bill of Materials” tracing components, equipment, software and raw-material origins through multiple supplier layers, a scope broader than a traditional software bill of materials.

The order defines a critical supply chain to include every tier of suppliers and subcontractors that provide goods, systems, software or services essential to contract delivery, mission assurance, security or resilience. The definition could bring software developers, cloud providers, managed service providers and other technology firms into compliance obligations even when they are several layers removed from a prime contractor.

Contractors must establish written procedures to vet suppliers and subcontractors. Reviews must examine financial stability, foreign ownership or influence, and manufacturing and supply risks. Vetting is expected to identify sole-source dependencies, inadequate production capacity, supplier concentration and overreliance on single sources.

Foreign ownership, control or influence is partly defined by whether a foreign interest could gain unauthorized access to information or adversely affect performance of a national security contract. Agencies will be directed to prohibit use of covered materials from unreliable foreign suppliers, subject to limited exceptions. Where contractors rely on an unreliable foreign supplier, they must qualify and transition to an alternative source as soon as practicable or face suspension, termination or other contract actions.

After vetting, contractors must mitigate identified risks and track corrective actions to closure. Significant supply chain risks identified through vetting must be reported to the Department of War within 15 days of completing the review. Contractors then have 45 days to submit a confidential corrective action plan with timelines and must file a closeout report after mitigations are completed. The order does not define “significant” risk and does not convert the 15-day window into a general cybersecurity incident-reporting deadline.

The order tightens waiver rules under 10 U.S.C. § 4872. Beginning Jan. 1, 2027, waivers allowing acquisition of covered materials from prohibited sources will generally stop unless a prime or subcontractor provides a formal mitigation plan that identifies the non-compliant source, documents efforts to find compliant alternatives and includes a timeline to remove the material. Contractors who commit fraud or knowingly fail to carry out approved mitigation plans may face contractual penalties and referral to the Attorney General.

The supply chain maps the order requires could create sensitive data security risks. Detailed records linking defense systems to software dependencies, suppliers, manufacturing locations and raw-material origins would be targets for foreign intelligence services and other threat actors. The order permits sharing bill-of-materials information with government support contractors when necessary, while requiring protection of proprietary information. Contractors will likely need access controls, encryption, audit logging, data loss prevention and compartmentalization to protect that information.

The Department of War is directed to use tools, including artificial intelligence, to analyze contractor acquisition data to identify vulnerabilities, bottlenecks and single points of failure. Use of AI could enable analysis of large supplier networks and raises questions about the accuracy of risk determinations, protection of proprietary information and security of centralized government supply chain databases.

The executive order does not set specific technical cybersecurity standards such as encryption levels or secure development requirements. It expands responsibilities for cybersecurity teams, third-party risk managers and compliance functions across the defense industrial base. The practical effects will depend on which acquisitions are designated national security-related and on the content of the forthcoming regulations.

Articles by this author